JarService malware hijacks automotive infotainment systems via legitimate update channels
Security researchers at Kaspersky have identified the JarService malware, which exploits a vulnerability in the TWCore update application of DoFun automotive head units to recruit devices into the BadBox botnet. This marks the first documented instance of malware specifically targeting automotive infotainment systems via a legitimate firmware update channel to perform ad fraud and traffic proxying.
Key Takeaways
- Kaspersky identified JarService exploiting the TWCore update application to install unauthorized software on DoFun head units
- The malware deploys a Trojan clicker for ad fraud and a reverse proxy module to route malicious traffic
- Human Security linked the campaign to MoYu Group, the operators behind the persistent BadBox botnet
- Infections are confined to infotainment hardware and do not grant control over physical vehicle driving functions
Why It Matters
The discovery of JarService malware targeting automotive infotainment systems signals a shift in ad fraud tactics toward high-bandwidth, internet-connected vehicle displays. As streaming platforms increasingly integrate with Android-based head units, these devices become lucrative targets for botnet operators seeking to mask fraudulent traffic through legitimate consumer hardware. This development forces a collision between automotive supply chain security and digital advertising integrity, as manufacturers must now defend against sophisticated firmware-level exploits previously seen in smart TVs. Watch for whether other infotainment hardware vendors disclose similar vulnerabilities in their proprietary update mechanisms following Kaspersky's notification to DoFun.
Additional Context
Kaspersky's JarService discovery extends a botnet ecosystem that has been building since at least 2023. The BadBox network, which JarService recruits devices into, was first identified by Human Security researchers in 2024 as a massive residential proxy operation built on compromised Android TV devices, with estimates exceeding 200,000 infected units at peak. Human Security's Lindsay Kaye and team traced the operation to Chinese-language forums where access to the proxy network was sold to fraud operators. The migration from living-room set-top boxes to automotive head units represents a logical expansion of that infrastructure, since both device classes run Android with persistent internet connections and limited user monitoring.
The DoFun and MoYu Group supply chain raises questions about automotive component vetting that regulators are beginning to address. The European Union's Cyber Resilience Act, which entered into force in December 2024, will require manufacturers of connected products to provide security updates for the entire expected product lifetime, with penalties of up to 15 million euros or 2.5 percent of global annual turnover for non-compliance. Automotive infotainment units sold in the EU after the Act's full application date in December 2027 will fall under these obligations. In the United States, the Federal Trade Commission issued a policy statement in January 2025 warning that companies selling connected devices without reasonable security measures may face enforcement actions under Section 5 of the FTC Act. These regulatory frameworks could accelerate scrutiny of how Tier-1 suppliers like DoFun handle firmware update integrity.
From a technical standpoint, the TWCore update mechanism exploited by JarService follows a pattern seen in previous IoT botnet campaigns. Kaspersky researchers detailed in their analysis that the malware achieves persistence by replacing the legitimate TWCore binary on the device's system partition, making removal difficult without a full factory reflash. The approach mirrors techniques documented in the 2023 ADB.Miner campaign, which compromised over 1.2 million Android TV and streaming devices by exploiting exposed Android Debug Bridge interfaces, according to reporting from BleepingComputer. The key difference with JarService is the attack vector: rather than exploiting a network-exposed service, it abuses a trusted over-the-air update path, which is significantly harder for endpoint security tools to flag without disrupting legitimate firmware delivery. For streaming platforms integrated into automotive infotainment, this means ad-fraud detection systems must now account for traffic originating from vehicle IP addresses that appear residential but are actually proxied through compromised head units.
Read full article at kobaran.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source